Unrated severityNVD Advisory· Published Apr 24, 2006· Updated Jun 16, 2026
CVE-2006-1991
CVE-2006-1991
Description
The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/php7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/php8&distro=openSUSE%20Tumbleweed
< 7.4.24-1.1+ 1 more
- (no CPE)range: < 7.4.24-1.1
- (no CPE)range: < 8.0.11-1.1
Patches
Vulnerability mechanics
References
12- secunia.com/advisories/20269nvdPatchVendor Advisory
- www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02nvdExploit
- secunia.com/advisories/20052nvdVendor Advisory
- secunia.com/advisories/20676nvdVendor Advisory
- secunia.com/advisories/21125nvdVendor Advisory
- www.vupen.com/english/advisories/2006/1500nvdVendor Advisory
- security.gentoo.org/glsa/glsa-200605-08.xmlnvd
- securitytracker.com/idnvd
- www.mandriva.com/security/advisoriesnvd
- www.novell.com/linux/security/advisories/2006_31_php.htmlnvd
- www.ubuntu.com/usn/usn-320-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/26003nvd
News mentions
0No linked articles in our index yet.